CVE-2025-48877
- EPSS 0.16%
- Veröffentlicht 09.06.2025 12:36:29
- Zuletzt bearbeitet 25.09.2025 20:27:42
Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch, Codepen is present in the default `allowed_iframes` si...
CVE-2025-48062
- EPSS 0.07%
- Veröffentlicht 09.06.2025 12:33:57
- Zuletzt bearbeitet 26.09.2025 13:05:09
Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch, certain invites via email may result in HTML injection...
CVE-2025-48053
- EPSS 0.15%
- Veröffentlicht 09.06.2025 12:30:33
- Zuletzt bearbeitet 25.09.2025 20:27:48
Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch, sending a malicious URL in a PM to a bot user can caus...
CVE-2025-46813
- EPSS 0.49%
- Veröffentlicht 05.05.2025 20:15:21
- Zuletzt bearbeitet 26.09.2025 12:54:49
Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fdee060d44accdee7679d66d778d1136510 and 82d84af6b0efbd9fa2aeec3e91ce7be1a768511b. On login-required sites, the leak meant that some ...
CVE-2025-32376
- EPSS 0.21%
- Veröffentlicht 30.04.2025 14:55:21
- Zuletzt bearbeitet 16.05.2025 16:28:51
Discourse is an open-source discussion platform. Prior to versions 3.4.3 on the stable branch and 3.5.0.beta3 on the beta branch, the users limit for a DM can be bypassed, thus giving the ability to potentially create a DM with every user from a site...
CVE-2025-24808
- EPSS 0.1%
- Veröffentlicht 26.03.2025 14:15:32
- Zuletzt bearbeitet 06.11.2025 22:05:03
Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on the `beta` branch, someone who is about to reach the limit of users in a group DM may send requests to add new users in parallel. T...
CVE-2025-24972
- EPSS 0.14%
- Veröffentlicht 26.03.2025 14:15:13
- Zuletzt bearbeitet 27.03.2025 16:45:27
Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on the `beta` branch, in specific circumstances, users could be added to group direct messages despite disabling direct messaging in t...
CVE-2024-53266
- EPSS 0.12%
- Veröffentlicht 04.02.2025 22:15:40
- Zuletzt bearbeitet 25.09.2025 20:27:24
Discourse is an open source platform for community discussion. In affected versions with some combinations of plugins, and with CSP disabled, activity streams in the user's profile page may be vulnerable to XSS. This has been patched in the latest ve...
CVE-2024-53851
- EPSS 0.32%
- Veröffentlicht 04.02.2025 22:15:40
- Zuletzt bearbeitet 26.09.2025 13:04:59
Discourse is an open source platform for community discussion. In affected versions the endpoint for generating inline oneboxes for URLs wasn't enforcing limits on the number of URLs that it accepted, allowing a malicious user to inflict denial of se...
CVE-2024-53994
- EPSS 0.15%
- Veröffentlicht 04.02.2025 22:15:40
- Zuletzt bearbeitet 25.09.2025 20:27:19
Discourse is an open source platform for community discussion. In affected versions users who disable chat in preferences could still be reachable in some cases. This problem has been patched in the latest version of Discourse. Users are advised to u...